LoginController.php 26 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731
  1. <?php
  2. declare (strict_types = 1);
  3. namespace App\Controller;
  4. use App\JsonRpc\UserServiceInterface;
  5. use App\Tools\CommonService;
  6. use App\Tools\PublicData;
  7. use App\Tools\Result;
  8. use Hyperf\Context\Context;
  9. use PHPStan\Type\Accessory\OversizedArrayType;
  10. use PHPUnit\Exception;
  11. use function Hyperf\Support\env;
  12. use Hyperf\Di\Annotation\Inject;
  13. use Hyperf\HttpServer\Annotation\AutoController;
  14. use Hyperf\Validation\Contract\ValidatorFactoryInterface;
  15. use \Phper666\JWTAuth\JWT;
  16. use App\Model\UserToken;
  17. use Hyperf\HttpServer\Response;
  18. use Hyperf\HttpMessage\Cookie\Cookie;
  19. use App\Controller\UserController;
  20. use App\JsonRpc\WebsiteServiceInterface;
  21. /**
  22. * @AutoController()
  23. */
  24. class LoginController extends AbstractController
  25. {
  26. #[Inject]
  27. protected ValidatorFactoryInterface $validationFactory;
  28. // protected JWT $JWT;
  29. /**
  30. * @var UserServiceInterface
  31. */
  32. #[Inject]
  33. private $userServiceClient;
  34. /**
  35. * @var WebsiteServiceInterface
  36. */
  37. #[Inject]
  38. private $websiteServiceClient;
  39. /**
  40. * @var Response
  41. */
  42. // private $response;
  43. // public function __construct(Jwt $JWT)
  44. // {
  45. // $this->JWT = $JWT;
  46. // }
  47. public function login(Jwt $jwt)
  48. {
  49. $reqData = $this->request->all();
  50. $validator = $this->validationFactory->make(
  51. $reqData,
  52. [
  53. 'username' => 'required',
  54. 'password' => 'required',
  55. 'type' => 'required',
  56. // 'code' => 'required',
  57. ],
  58. [
  59. 'username.required' => '用户名不能为空',
  60. 'password.required' => '密码不能为空',
  61. 'type.required' => '登录方式必填',
  62. // 'code.required' => 'code方式必填',
  63. ]
  64. );
  65. if ($validator->fails()) {
  66. $errorMessage = $validator->errors()->first();
  67. return Result::error($errorMessage);
  68. }
  69. // $comm = new CommonService();
  70. // $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  71. // $code = $redis->get($reqData['code']);
  72. // if (empty($code)) {
  73. // return Result::error("验证码已过期");
  74. // }
  75. // if (strtolower($code) != strtolower($reqData['captcha'])) {
  76. // return Result::error("验证码错误");
  77. // }
  78. $where = [];
  79. if ($reqData['type'] == 1) { //密码登录
  80. $where = [
  81. 'user_name' => $reqData['username'],
  82. ];
  83. }
  84. $userInfos = $this->userServiceClient->verifyUserInfo($where);
  85. if ($userInfos['code'] == 0) {
  86. return Result::error("用户不存在");
  87. }
  88. if($userInfos['data']['status']==0){
  89. return Result::error("用户已经冻结");
  90. }
  91. if (md5(md5($reqData['password']) . $userInfos['data']['salt']) != $userInfos['data']['password']) {
  92. return Result::error("登陆密码错误");
  93. }
  94. if($userInfos['data']['type_id']!=10000){
  95. $authData = [
  96. 'id'=>$userInfos['data']['sszq'],
  97. 'SiteId'=>Context::get("SiteId")
  98. ];
  99. var_dump("参数:",$authData);
  100. $resultAuth = $this->checkUserAuth($authData);
  101. if(!$resultAuth){
  102. return Result::error("您没有权限登陆此网站");
  103. }
  104. }
  105. $userData = [
  106. 'uid' => $userInfos['data']['id'], // 如果使用单点登录,必须存在配置文件中的sso_key的值,一般设置为用户的id
  107. 'user_name' => $userInfos['data']['user_name'],
  108. 'mobile' => $userInfos['data']['mobile'],
  109. 'email' => $userInfos['data']['email'],
  110. 'level_id' => $userInfos['data']['level_id'],
  111. 'type_id' => $userInfos['data']['type_id'],
  112. ];
  113. // 使用默认场景登录
  114. $token = $jwt->getToken('default', $userData);
  115. // 检查是否有旧的token
  116. $old_token = UserToken::where('user_id', $userData['uid'])->first();
  117. if (!empty($old_token)) {
  118. $jwt->logout($old_token->token);
  119. try {
  120. $jwt->verifyToken($old_token->token);
  121. }catch (\Exception $exception){
  122. $code = $exception->getCode();
  123. if ($code== 400) {
  124. $new_token = UserToken::where('user_id', $userData['uid'])->update(['token' => $token->toString()]);
  125. if (empty($new_token)) {
  126. return Result::error("Token过期失败!");
  127. }
  128. } else{
  129. return Result::error("Token过期失败!");
  130. }
  131. }
  132. }else{
  133. $usernew_token = $token->toString();
  134. $user_token = UserToken::create([
  135. 'user_id' => $userData['uid'],
  136. 'token' => $usernew_token
  137. ]);
  138. if (empty($user_token)) {
  139. return Result::error("登录失败!");
  140. }
  141. }
  142. $data = [
  143. 'token' => $token->toString(),
  144. 'exp' => $jwt->getTTL($token->toString()),
  145. ];
  146. return Result::success($data);
  147. }
  148. /**
  149. * @return void
  150. */
  151. public function checkVerifyCode(Jwt $jwt)
  152. {
  153. //其它信息暂时不管 先以openid
  154. $reqData = $this->request->all();
  155. $validator = $this->validationFactory->make(
  156. $reqData,
  157. [
  158. 'token' => 'required',
  159. ],
  160. [
  161. 'token.required' => 'token不能为空',
  162. ]
  163. );
  164. if ($validator->fails()) {
  165. $errorMessage = $validator->errors()->first();
  166. return Result::error($errorMessage);
  167. }
  168. $userInfo = $jwt->getClaimsByToken($reqData['token']);
  169. if ($userInfo) {
  170. return Result::success(['token' => $reqData['token']]);
  171. } else {
  172. return Result::error("token无效");
  173. }
  174. }
  175. /**
  176. * 注册或登陆
  177. * @return void
  178. */
  179. public function registerOrLogin(Jwt $jwt)
  180. {
  181. //获取access_token
  182. $reqData = $this->request->all();
  183. $validator = $this->validationFactory->make(
  184. $reqData,
  185. [
  186. 'code' => 'required',
  187. ],
  188. [
  189. 'code.required' => 'code不能为空',
  190. ]
  191. );
  192. if ($validator->fails()) {
  193. $errorMessage = $validator->errors()->first();
  194. return Result::error($errorMessage);
  195. }
  196. $url = env("WECHAT") . "cgi-bin/token?appid=" . env("APPID") . "&secret=" . env("APP_SECRET") . "&grant_type=client_credential";
  197. $result = PublicData::http_get($url);
  198. $accessTokenData = json_decode($result, true);
  199. //获取openid
  200. $url = env("WECHAT") . "sns/jscode2session?appid=" . env("APPID") . "&secret=" . env("APP_SECRET") . "&js_code=" . $reqData['loginCode'] . "&grant_type=authorization_code";
  201. $result = PublicData::http_get($url);
  202. $openInfoData = json_decode($result, true);
  203. if (isset($openInfoData['errcode']) && in_array($openInfoData['errcode'], [40163, 40029])) {
  204. return Result::error($openInfoData['errmsg']);
  205. }
  206. $data = [
  207. 'code' => $reqData['code'],
  208. 'openid' => $openInfoData['openid'],
  209. ];
  210. // 将数组转换为JSON字符串
  211. $jsonData = json_encode($data);
  212. // 初始化cURL会话
  213. $ch = curl_init(env("WECHAT") . "wxa/business/getuserphonenumber?access_token=" . $accessTokenData['access_token']);
  214. // 设置cURL选项 Todo 这里有一万个wc 封装成post方法就报错,后期再研究
  215. curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
  216. curl_setopt($ch, CURLOPT_POST, true);
  217. curl_setopt($ch, CURLOPT_POSTFIELDS, $jsonData);
  218. curl_setopt($ch, CURLOPT_HTTPHEADER, [
  219. 'Content-Type: application/json',
  220. 'Content-Length: ' . strlen($jsonData),
  221. ]);
  222. // 执行cURL会话
  223. $response = curl_exec($ch);
  224. // 检查是否有错误发生
  225. if (curl_errno($ch)) {
  226. return Result::error("获取手机号失败");
  227. }
  228. // 关闭cURL会话
  229. curl_close($ch);
  230. $response = json_decode($response, true);
  231. if ($response['errcode'] == '40029') {
  232. return Result::error($openInfoData['errmsg']);
  233. }
  234. // 打印响应内容
  235. var_dump($openInfoData, $response);
  236. //根据openid 获取token
  237. $checkUserInfo = $this->userServiceClient->verifyUserInfo([
  238. 'user_name' => $response['phone_info']['purePhoneNumber'],
  239. ]);
  240. if ($checkUserInfo['code'] == 0) {
  241. $salt = rand(1, 999999);
  242. $createUserData = [
  243. 'user_name' => $response['phone_info']['purePhoneNumber'],
  244. 'salt' => $salt,
  245. 'password' => $openInfoData['openid'],
  246. 'type_id' => 20000,
  247. ];
  248. $checkUserInfo = $this->userServiceClient->createUser($createUserData);
  249. }
  250. //根据openid和手机号判断是否注册,未注册直接注册
  251. $wechatReqData = [
  252. 'openid' => $openInfoData['openid'],
  253. 'purePhoneNumber' => $response['phone_info']['purePhoneNumber'],
  254. ];
  255. $wechatInfo = $this->userServiceClient->getWechatInfo($wechatReqData);
  256. if ($wechatInfo['code'] == 0) {
  257. $wechatData = [
  258. 'openid' => $openInfoData['openid'],
  259. 'phoneNumber' => $response['phone_info']['phoneNumber'],
  260. 'purePhoneNumber' => $response['phone_info']['purePhoneNumber'],
  261. 'countryCode' => $response['phone_info']['countryCode'],
  262. 'watermark' => json_encode($response['phone_info']['watermark']),
  263. 'user_id' => $checkUserInfo['data']['id'],
  264. ];
  265. $this->userServiceClient->addWechatInfo($wechatData);
  266. }
  267. var_dump($checkUserInfo);
  268. $userData = [
  269. 'uid' => $checkUserInfo['data']['id'], // 如果使用单点登录,必须存在配置文件中的sso_key的值,一般设置为用户的id
  270. 'user_name' => $response['phone_info']['phoneNumber'],
  271. 'mobile' => $checkUserInfo['data']['mobile'] ?? '',
  272. 'email' => $checkUserInfo['data']['email'],
  273. // 'rong_token' => $userInfos['data']['rong_token'],
  274. 'level_id' => $checkUserInfo['data']['level_id'],
  275. 'type_id' => $checkUserInfo['data']['type_id'],
  276. ];
  277. // 使用默认场景登录
  278. $token = $jwt->getToken('default', $userData);
  279. $data = [
  280. 'token' => $token->toString(),
  281. 'exp' => $jwt->getTTL($token->toString()),
  282. ];
  283. return Result::success($data);
  284. }
  285. public function getToken(JWT $jwt)
  286. {
  287. $reqData = $this->request->all();
  288. $userInfos = $this->userServiceClient->getUserInfo((int) $reqData['id']);
  289. $userData = [
  290. 'uid' => $userInfos['data']['id'], // 如果使用单点登录,必须存在配置文件中的sso_key的值,一般设置为用户的id
  291. 'user_name' => $userInfos['data']['user_name'],
  292. 'mobile' => $userInfos['data']['mobile'],
  293. 'email' => $userInfos['data']['email'],
  294. 'level_id' => $userInfos['data']['level_id'],
  295. 'type_id' => $userInfos['data']['type_id'],
  296. ];
  297. var_dump($userInfos);
  298. // 使用默认场景登录
  299. $token = $jwt->getToken('default', $userData);
  300. return Result::success($token->toString());
  301. }
  302. public function httpPost()
  303. {
  304. }
  305. # http头部必须携带token才能访问的路由
  306. public function getData(Jwt $jwt)
  307. {
  308. // var_dump($this->UserId);
  309. $h = $this->request->getHeaders();
  310. // var_dump($this->request->getHeaders());
  311. // $a= 'eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpc3MiOiJwaHBlcjY2Ni9qd3QiLCJ1aWQiOjMyLCJ1c2VyX25hbWUiOiIxIiwicm9sZV9pZCI6MSwibW9iaWxlIjoiMTU4MDEyNDU3NTUiLCJlbWFpbCI6IjVAcXEuY29tIiwicm9uZ190b2tlbiI6IiIsImxldmVsX2lkIjo4LCJqd3Rfc2NlbmUiOiJkZWZhdWx0IiwianRpIjoiZGVmYXVsdF82Njc1MjJkZDQ3YWYxMi41MTE5MjI5MiIsImlhdCI6MTcxODk1MjY2OSwibmJmIjoxNzE4OTUyNjY5LCJleHAiOjE3MjE1NDQ2Njl9.e0JW8fgNrwBdFgmQ8GNtES2ME1SbcbIih5MsQWzT6sk';
  312. $arr = $jwt->getClaimsByToken($h['token'][0]);
  313. var_dump($h['token'][0], "+++++++++++", $arr, "===####");
  314. return $this->response->json(['code' => 0, 'msg' => 'success', 'data' => ['a' => 1]]);
  315. }
  316. /**
  317. * 检测用户权限
  318. * @return void
  319. */
  320. public function checkUserAuth($data)
  321. {
  322. // var_dump("进没进来呢::",$data);
  323. $websiteGroup = [
  324. 'id'=>$data['id']
  325. ];
  326. $result = $this->userServiceClient->getWebsiteGroupInfo($websiteGroup);
  327. // var_dump("checkUserAuth:",$result);
  328. if($result['code']==200){
  329. if($data['SiteId'] && $result['data']['web_ids']){
  330. if(in_array($data['SiteId'],json_decode($result['data']['web_ids'],true))){
  331. return true;
  332. }else{
  333. return false;
  334. }
  335. }else{
  336. return false;
  337. }
  338. }
  339. }
  340. /**
  341. * 查询登陆状态
  342. * @return array
  343. * @throws \Psr\Container\ContainerExceptionInterface
  344. * @throws \Psr\Container\NotFoundExceptionInterface
  345. * @throws \RedisException
  346. */
  347. public function loginStatus(Jwt $jwt)
  348. {
  349. $header = $this->request->getHeader('userurl');
  350. $origin = $header[0];
  351. $logindevice = explode("//", $origin);
  352. if(!isset($logindevice[1]) && !$logindevice[1]){
  353. return Result::error('userurl不存在,请登录');
  354. }
  355. $reqData = $this->request->all();
  356. $validator = $this->validationFactory->make(
  357. $reqData,
  358. [
  359. 'token' => 'required',
  360. ],
  361. [
  362. 'token.required' => 'token不能为空',
  363. ]
  364. );
  365. if ($validator->fails()) {
  366. $errorMessage = $validator->errors()->first();
  367. return Result::error($errorMessage);
  368. }
  369. try {
  370. $jwt->verifyToken($reqData['token']);
  371. $results = $this->checkAuth([
  372. 'token'=>$reqData['token'],
  373. 'userurl'=>$logindevice[1]
  374. ]);
  375. if($results['code']==200){
  376. return Result::success(['isLogin' => true]);
  377. }else{
  378. return Result::error("没有权限登陆".$logindevice[1]."这个域名");
  379. }
  380. }catch(\Exception $e){
  381. return Result::error('token已过期:'.$e->getMessage());
  382. }
  383. }
  384. /**
  385. *登陆
  386. * @return void
  387. */
  388. public function loginapi()
  389. {
  390. $reqData = $this->request->all();
  391. $validator = $this->validationFactory->make(
  392. $reqData,
  393. [
  394. 'token' => 'required',
  395. ],
  396. [
  397. 'token.required' => 'token不能为空',
  398. ]
  399. );
  400. if ($validator->fails()) {
  401. $errorMessage = $validator->errors()->first();
  402. return Result::error($errorMessage);
  403. }
  404. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  405. $ticket = md5($reqData['token']);
  406. $res = $redis->set('ticket:' . $ticket, $reqData['token'], 3600*24);
  407. if ($res){
  408. return Result::success(['ticket' => $ticket ,'isSave' => 1]);
  409. } else {
  410. return Result::error('存储失败');
  411. }
  412. }
  413. public function logoutapi(Jwt $jwt)
  414. {
  415. $reqData = $this->request->all();
  416. $validator = $this->validationFactory->make(
  417. $reqData,
  418. [
  419. 'token' => 'required',
  420. ],
  421. [
  422. 'token.required' => 'token不能为空',
  423. ]
  424. );
  425. if ($validator->fails()) {
  426. $errorMessage = $validator->errors()->first();
  427. return Result::error($errorMessage);
  428. }
  429. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  430. $ticket = md5($reqData['token']);
  431. $isDel = 0;
  432. if ($redis->exists('ticket:' . $ticket)) {
  433. $res = $redis->del('ticket:' . $ticket);
  434. if (!!$res && $res == 1) $isDel = 1;
  435. }else{
  436. $isDel = 1;
  437. }
  438. try {
  439. $jwt->logout($reqData['token']);
  440. }catch (\Exception $e){
  441. return Result::success(['isDel' => $isDel]);
  442. }
  443. return Result::success(['isDel' => $isDel]);
  444. }
  445. public function goLogin()
  446. {
  447. // 获取请求数据并设置默认值
  448. $reqData = $this->request->all();
  449. // 安全过滤 Admin-Token 和 ticket
  450. $cookieList = $this->request->getCookieParams();
  451. // 安全过滤 Admin-Token 和 ticket
  452. $adminToken = !empty($cookieList['Admin-Token']) ? $this->sanitizeInput($cookieList['Admin-Token']) : '';
  453. $ticket = !empty($reqData['ticket']) ? $this->sanitizeInput($reqData['ticket']) : '';
  454. $backurl = $this->sanitizeBackUrl($reqData['backurl'] ?? $_SERVER['HTTP_REFERER'] ?? '');
  455. // 校验 THE_HOST 环境变量
  456. $theHost = env("THE_HOST");
  457. if (empty($theHost)) {
  458. return Result::error('系统配置错误:THE_HOST 未定义');
  459. }
  460. var_dump("admintoken:",$adminToken);
  461. // 如果存在 adminToken,则进行登录校验
  462. if (!empty($adminToken)) {
  463. // 处理登录
  464. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  465. var_dump("ticket1111:",$ticket);
  466. if(!empty($ticket)){
  467. if (!empty($ticket) && $redis->exists('ticket:' . $ticket)) {
  468. if(isset($reqData['userurl']) && $reqData['userurl']){
  469. $resultR = $this->checkAuth([
  470. 'token'=>$redis->get('ticket:' . $ticket),
  471. 'userurl'=>$reqData['userurl']
  472. ]);
  473. if($resultR['code']==-1){
  474. return $this->response->redirect($this->fun_http('http://'.$theHost.'/#/loginAlert'), 302);
  475. }
  476. }else{
  477. $backurl = rtrim($backurl, '/');
  478. return $this->response->redirect($this->fun_http($backurl . '?ticket=' . $ticket . '&admintoken=' . urlencode($adminToken)), 302);
  479. }
  480. }else{
  481. var_dump("222222222:");
  482. return $this->response->redirect($this->fun_http('http://'.$theHost.'/#/login?backurl='.urlencode($backurl)), 302);
  483. }
  484. }else{
  485. $ticket = md5($adminToken);
  486. }
  487. var_dump("333333333333333:");
  488. return $this->response->redirect($this->fun_http($backurl . '?ticket=' . $ticket . '&admintoken=' . urlencode($adminToken)), 302);
  489. }else{
  490. var_dump("444444444444444:");
  491. return $this->response->redirect($this->fun_http('http://'.$theHost.'/#/login?backurl='.urlencode($backurl)), 302);
  492. }
  493. }
  494. /**
  495. * 安全过滤输入数据
  496. * @param string $input
  497. * @return string
  498. */
  499. private function sanitizeInput(string $input): string
  500. {
  501. return htmlspecialchars(trim($input), ENT_QUOTES, 'UTF-8');
  502. }
  503. /**
  504. * 校验并清理 backurl
  505. * @param string $backurl
  506. * @return string
  507. */
  508. private function sanitizeBackUrl(string $backurl): string
  509. {
  510. // 解码并去除多余字符
  511. $decodedUrl = urldecode($backurl);
  512. return filter_var($decodedUrl, FILTER_VALIDATE_URL) ?: '';
  513. }
  514. /**
  515. * 跳转到目标页面
  516. * @param string $backurl
  517. * @param string $ticket
  518. * @param string $adminToken
  519. */
  520. private function redirectWithTicket(string $backurl, string $ticket, string $adminToken)
  521. {
  522. $backurl = rtrim($backurl, '/');
  523. $redirectUrl = $this->fun_http($backurl . '?ticket=' . $ticket . '&admintoken=' . urlencode($adminToken));
  524. // $loginUrl = 'http://' . $theHost . '/#/login?backurl=' . urlencode($backurl);
  525. // return $this->response->redirect($loginUrl, 302);
  526. return $this->response->redirect($redirectUrl, 302);
  527. }
  528. /**
  529. * 处理 URL
  530. * @param string $url
  531. * @return string
  532. */
  533. private function fun_http(string $url): string
  534. {
  535. // 确保 URL 以 http 或 https 开头
  536. if (!preg_match('/^https?:\/\//i', $url)) {
  537. $url = 'http://' . $url;
  538. }
  539. return $url;
  540. }
  541. /**
  542. * 退出
  543. * @return void
  544. */
  545. public function logout(Jwt $jwt)
  546. {
  547. $reqData = $this->request->all();
  548. $validator = $this->validationFactory->make(
  549. $reqData,
  550. [
  551. 'backurl' => 'required',
  552. 'admintoken' => 'required',
  553. ],
  554. [
  555. 'backurl.required' => 'backurl不能为空',
  556. 'admintoken.required' => 'admintoken不能为空',
  557. ]
  558. );
  559. if ($validator->fails()) {
  560. $errorMessage = $validator->errors()->first();
  561. return Result::error($errorMessage);
  562. }
  563. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  564. $ticket = md5($reqData['admintoken']);
  565. $res = $redis->del('ticket:' . $ticket);
  566. var_dump("删除redis:", $res);
  567. var_dump("获取redis:", $redis->get('ticket:' . $ticket));
  568. // 获取所有 Cookie
  569. $cookies = $this->request->getCookieParams();
  570. var_dump("获取cookie:", $cookies);
  571. if($cookies){
  572. foreach ($cookies as $name => $value) {
  573. if($name){
  574. $expire = time() - 3600; // 设置过期时间为过去的时间
  575. $cookie = new Cookie((string)$name, '', $expire, '/');
  576. $this->response = $this->response->withCookie($cookie);
  577. }
  578. }
  579. }
  580. try {
  581. $jwt->logout($reqData['admintoken']);
  582. } catch (\Exception $e) {
  583. var_dump("返回错误信息:", $e->getMessage());
  584. }
  585. $backurl = $this->fun_http($reqData['backurl']);
  586. var_dump("返回地址:", $backurl);
  587. return $this->response->redirect($backurl, 302);
  588. }
  589. /**
  590. * 登录回调
  591. * @return void
  592. */
  593. public function backlogin()
  594. {
  595. $reqData = $this->request->all();
  596. var_dump("===============接收参数:",$reqData);
  597. $validator = $this->validationFactory->make(
  598. $reqData,
  599. [
  600. 'backurl' => 'required',
  601. 'token' => 'required',
  602. ],
  603. [
  604. 'backurl.required' => 'backurl不能为空',
  605. 'token.required' => 'token不能为空',
  606. ]
  607. );
  608. if ($validator->fails()) {
  609. $errorMessage = $validator->errors()->first();
  610. return Result::error($errorMessage);
  611. }
  612. $redis = $this->container->get(\Hyperf\Redis\Redis::class);
  613. $ticket = md5($reqData['token']);
  614. $res = $redis->set('ticket:' . $ticket, $reqData['token'], 3600*24);
  615. var_dump("===============返回值:",$res);
  616. $expire = time()+3600*24;
  617. $cookieName = 'Admin-Token';
  618. // 创建 Cookie 实例
  619. $cookie = new Cookie($cookieName, $reqData['token'], $expire, '/');
  620. // 清空 Cookie
  621. $r = $this->response = $this->response->withCookie($cookie);
  622. var_dump("设置token:", $r);
  623. if($res && !empty($ticket)){
  624. $url = $reqData['backurl'] . '/?ticket=' . $ticket . '&admintoken=' . urlencode($reqData['token']);
  625. $url = $this->fun_http($url);
  626. var_dump("跳转地址gogo:",$url);
  627. return $this->response->redirect($url, 302);
  628. }
  629. }
  630. /**
  631. * 检测用户是否有权限
  632. * @param $data
  633. * @return void
  634. * $data['token]
  635. * $data['userurl']
  636. */
  637. public function checkAuth($data)
  638. {
  639. $jwt = new JWT();
  640. $ver =$jwt->getClaimsByToken($data['token']);
  641. $tokenTime = $jwt->getTokenDynamicCacheTime($data['token']);
  642. if($tokenTime==0){
  643. return Result::error("token已过期,请重新登录",-1);
  644. }
  645. if(isset($data['userurl']) && $data['userurl']){
  646. $result = $this->websiteServiceClient->getWebsiteId(['website_url'=>$data['userurl']]);
  647. if(!isset($result['data']['id']) || !$result['data']['id']){
  648. return Result::error("网站不存在...",-1);
  649. }
  650. if($ver['type_id']!=10000){
  651. $userInfo = $this->userServiceClient->getUserInfo($ver['uid']);
  652. if($userInfo['code'] == 200 && isset($userInfo['data']) && !empty($userInfo['data']['sszq'])){
  653. $sszq = $userInfo['data']['sszq'];
  654. //组id
  655. $authData = [
  656. 'id' => $sszq,
  657. 'SiteId' => $result['data']['id']
  658. ];
  659. // 调用 LoginController 中的 checkUserAuth 方法
  660. $resultAuth = $this->checkUserAuth($authData);
  661. if (!$resultAuth) {
  662. // 如果没有权限,返回错误响应
  663. return Result::error("没有权限登陆此网站...",-1);
  664. }else{
  665. return Result::success([]);
  666. }
  667. }else{
  668. return Result::error("用户没有群组...",-1);
  669. }
  670. }else{
  671. return Result::success([]);
  672. }
  673. }else{
  674. return Result::error("userurl不能为空...",-1);
  675. }
  676. }
  677. }